# How to parse data in message into separate fields

**URL:** <https://discuss.elastic.co/t/how-to-parse-data-in-message-into-separate-fields/198209>\
**Category:** Logstash\
**Created:** [September 5, 2019, 9:29am UTC](https://discuss.elastic.co/t/how-to-parse-data-in-message-into-separate-fields/198209 "2019-09-05T09:29:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nurbek](https://avatars.discourse-cdn.com/v4/letter/n/f1d935/32.png) [@Nurbek](https://discuss.elastic.co/u/Nurbek)\
**Post date:** [September 5, 2019, 9:29am UTC](https://discuss.elastic.co/t/how-to-parse-data-in-message-into-separate-fields/198209/1 "2019-09-05T09:29:21Z")

</div>

![photo_2019-09-04_12-24-47](https://us1.discourse-cdn.com/elastic/original/3X/e/e/ee0d5b7521b873e8c84b2e5e9665988201d8c3d1.jpeg)

This is my data in KIbana

```
input {
  http_poller {
    urls => {
      soap_request => {
					method => post
					url => "URL deleted"
		headers => {
					"Content-Type" => "text/xml; charset=utf-8"
					"SOAPAction" => "URL deleted"
					}
        body => '<soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope" xmlns:req="http://localhost/request">
					   <soap:Header/>
					   <soap:Body>
						  <req:GetDocuments>
							 <req:Date1>2019-08-01</req:Date1>
							 <req:Date2>2019-08-31</req:Date2>
						  </req:GetDocuments>
					   </soap:Body>
					</soap:Envelope>'
		auth => {
				user => "1"
				password => "1"
				}
			  }
			}
		schedule => { cron => "* * * * * UTC"}
				request_timeout => 60
				 codec => multiline {
			pattern => "<m:Document>" 
            what => "previous"
			}
										
		}
	}
	
	filter {
     xml {
        source => "message"
		target => "xmldata"
        store_xml => false
        xpath => [
            "//Status/text()", "Status",
			"//Number/text()", "Number",
			"//Tip/text()", "Tip",
			"//m:DataDoc/text()", "Data"
			         ]
    }
}
		
output {
    elasticsearch {
        hosts => ['localhost:9200']
        index => "xml222"
    }
    stdout {
        codec => rubydebug
    }
}

```

This is my Logstash config but it is doesn't work

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2019, 9:29am UTC](https://discuss.elastic.co/t/how-to-parse-data-in-message-into-separate-fields/198209/2 "2019-10-03T09:29:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
